Switching between private and non-private states

By automatically detecting privacy trigger phrases and historical behaviors, using machine learning models to determine whether the message content is sensitive, and switching the application to private state or blurring the information when necessary, it solves the problem of users forgetting to manually switch to private state and achieves more efficient information protection.

CN114579989BActive Publication Date: 2025-09-12GOOGLE LLC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210048001.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2017-02-17
Filing Date
2017-11-17
Publication Date
2025-09-12
Estimated Expiration
2037-11-17

AI Technical Summary

Technical Problem

In the prior art, when users use messaging applications such as chat and email, they need to manually switch to a private state to protect sensitive information, and they are prone to forgetting to switch, resulting in the accidental retention or leakage of sensitive information.

Method used

By detecting signals such as privacy trigger phrases, n-grams, and historical behaviors, machine learning models are used to automatically determine whether the message content is sensitive, and if necessary, the application will be switched to private state or sensitive information will be blurred.

Benefits of technology

It reduces user interaction, improves information security, and avoids the storage or leakage of sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114579989B_ABST
    Figure CN114579989B_ABST
Patent Text Reader

Abstract

The present application relates to transitioning between a private state and a non-private state, and in particular to automatically transitioning applications (particularly those that enable the exchange of messages between users) into and / or out of a private state based on various signals associated with the messages and / or the participants themselves. In various embodiments, an ongoing message exchange topic between two or more participants operating two or more corresponding message exchange clients can be examined. Based at least in part on this examination, a probability can be determined that a message directed from one of the participants to another of the participants as part of the ongoing message exchange topic would be considered private by at least a given one of the two or more participants. A determination can be made as to whether the determined probability meets one or more thresholds, and in response, one or more of the message exchange clients can be transitioned into a private state.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description of the case

[0002] This application is a divisional application of Chinese invention patent application No. 201711144486.6, filed on November 17, 2017. Background Art

[0003] A message exchange thread, such as a chat, email exchange, or text messaging, may contain information that may be sensitive (e.g., confidential) to one or more of the participants. Participants in a message exchange thread may desire that at least some of the content of the message exchange thread not be retained (e.g., in a log) or at least be available in its original, sensitive form. Many internet applications allow users to switch the application to a private state (e.g., "Off the Record," "Incognito mode," "InPrivate," etc.) if the user is engaging in an activity that the user deems sensitive. However, in most cases—particularly in the case of messaging clients such as chat clients, text messaging clients, and email clients—this switch must be manually initiated by the user. Furthermore, the user must also switch the application out of private state; this typically does not occur automatically, particularly in messaging clients. Consequently, information that the user would otherwise prefer to keep confidential or not retain at all may be accidentally retained or stored (e.g., in a message exchange log, as a transcript of the message exchange thread, etc.) because the user forgot to switch the application to private state. This retained information could potentially be exposed to unauthorized parties. Likewise, if a user forgets to take an application, such as a chat client, out of private mode, the user may accidentally lose content that the user would have preferred to keep. Summary of the Invention

[0004] This specification is generally directed to a technique for automatically transitioning applications (particularly those that enable the exchange of messages between users (e.g., such as chat applications, email clients, web pages that facilitate message exchange threads, etc.) into a private state (and, in some cases, out of a private state) based on various signals associated with the messages and / or the participants themselves. Once in a private state, information deemed sensitive (e.g., confidential) can be obfuscated (e.g., names or other sensitive words or phrases can be scrambled), or the application can avoid storing (e.g., in logs or transcriptions of message exchange threads) sensitive information.

[0005] Automatically transitioning an application to a private state (and, in some cases, out of a private state) can have a number of advantages. This can include reducing the amount of interaction required between the user and their device, thereby reducing the processing required to process such information, etc. Additionally, in some cases, the security of user data can be improved, for example, because the data is not stored or is obfuscated.

[0006] In various embodiments, an ongoing message exchange topic between one or more participants can be centrally inspected, for example, at a separate message exchange client operated by a separate participant and / or at one or more servers facilitating the message exchange topic. Based on the inspection, a probability can be determined (e.g., calculated) that one or more messages directed from one of the participants to another of the participants as part of the ongoing message exchange topic would be considered private by at least a given participant. This probability can be determined in various ways based on various signals.

[0007] In some embodiments, the likelihood may be determined based on the content of one or more messages themselves. For example, in some embodiments, certain phrases may be classified as "privacy trigger phrases" that, when detected, cause one or more message exchange clients operated by participants in an ongoing message exchange topic to transition to a private state. These privacy trigger phrases may include phrases such as "off the record," "let's keep this between us," "can you promise to not tell anyone?", etc. In some such embodiments, one or more messages immediately following (and, in some instances, preceding) such privacy trigger phrases may not be retained, for example, until the user manually takes the message exchange client out of the private state or until it is detected that the topic of discussion has changed to a less sensitive subject.

[0008] In other embodiments, specific n-grams or combinations of n-grams (whether adjacent or not) can be used to trigger a transition to a private state. For example, suppose a user provides the statement "I heard Bill is getting fired because he was caught stealing money" to a message exchange topic. N-grams such as "fired," "caught," and "stealing" can trigger a transition to a private state, either individually or in combination. In some embodiments, one or more bound entity names (e.g., "Bill") in the n-gram can trigger this transition to a private state. In some such embodiments, when in a private state, the statement can be obfuscated (e.g., "I heard *is getting fired because *was caught stealing money") when it is persisted (e.g., as part of a transcription of the message exchange topic), such that the potentially user-identified n-grams are no longer available. In other embodiments, the entire statement can be redacted or simply not stored in the message exchange topic.

[0009] Additionally or alternatively, in some embodiments, one or more other signals associated with one or more message exchange participants can be used to determine the likelihood that one or more messages exchanged in a message exchange topic will be considered private by at least one participant. In some embodiments, historical behavior associated with one or more of the message exchange topic participants, or in some cases, generally associated with message exchange topic participants (i.e., participants in other message exchange topics), can be considered. Historical behavior can include, for example, browsing history of one or more participants, historical utilization of browser private states by one or more participants, historical utilization of private states associated with message exchange clients by one or more participants, and the like. For example, assume that one or more employees in an employer-facilitated message exchange topic manually transition their respective message exchange clients to a private state whenever a topic is discussed as part of the employer-facilitated message exchange topic. In various embodiments, such historical behavior associated with these employees can be "learned" so that similar behavior can later be detected and trigger an automatic transition to a private state.

[0010] In some embodiments, one or more trained machine learning models (such as convolutional neural network models and / or recurrent neural network models) can be employed to determine the likelihood that message exchange content will be considered private by one or more participants. For example, the machine learning model can be trained using labeled training examples associated with instances in which participants in a message exchange topic manually transitioned their message exchange clients to a private state. Features of these training examples can include, for example, n-grams contained in the message exchange topic, phrases contained in the message exchange topic (e.g., "can you keep this between us"), contextual cues (e.g., the identities of the participants, the locations of the participants, etc.), historical user behavior associated with one or more participants, and the like. Once the machine learning model is trained, it can be applied across multiple inputs, such as at a separate computing device operating a message exchange client or at a central node facilitating a message exchange topic, to determine the likelihood that one or more participants in the message exchange topic, given an input, will consider at least a portion of the message exchange topic private. In some embodiments, such a machine learning model can be stored and / or applied on the computing devices of the individual participants.

[0011] In various embodiments, the likelihood that a particular message exchange topic participant will treat at least a portion of the message exchange topic as private can be compared to one or more thresholds. For example, the likelihood can be calculated numerically (e.g., in the range of 1 to 100, 0.0 to 1.0, etc.) and compared to a certain minimum threshold (e.g., 60, 0.7, etc.). If the likelihood exceeds the minimum threshold, the message exchange client operated by the message exchange topic participant can be transitioned to a private state. In some embodiments, a prompt can be provided to the participant (e.g., by the message exchange client) requesting permission to transition the message exchange client to a private state. In other embodiments, permission may not be requested. In further other embodiments, permission to transition to a private state can be requested only when the likelihood measure meets a first minimum threshold (e.g., 50, 0.5) rather than a second, e.g., higher, threshold (e.g., 80, 0.8).

[0012] If only the message exchange client of a single participant is transformed into a private state, the message exchange topic content that is considered to be potentially private may not be retained on the computing device of the participant, but may be retained on the computing devices of other participants. Therefore, in some embodiments, if the message exchange client of a single participant is transformed into a private state, the message exchange client (or some other component, such as a central cloud-based component that manages the message exchange topic) can send a command for transforming into a private state to the message exchange clients of other participants. In some embodiments, other participants may be prompted for permission to enter a private state (e.g., at their corresponding message exchange clients), e.g., with an explanation of why. In other embodiments, the message exchange clients of other participants may be automatically transformed into a private state.

[0013] In some embodiments, a method performed by one or more processors is provided, the method comprising: examining, by the one or more processors, an ongoing message exchange topic between two or more participants operating two or more corresponding message exchange clients; determining, by one or more of the processors, at least in part based on the examining, a likelihood that one or more messages directed from one of the two or more participants to another of the two or more participants as part of the ongoing message exchange topic would be considered private by at least a given one of the two or more participants; determining, by one or more of the processors, that the determined likelihood satisfies one or more thresholds; and transitioning one or more of the two or more message exchange clients to a private state in response to determining that the determined likelihood satisfies the one or more thresholds.

[0014] These and other embodiments may optionally include one or more of the following features. In various embodiments, determining the likelihood may be based, at least in part, on the content of one or more messages forming part of the ongoing message exchange topic. In various embodiments, determining the likelihood may also be based on historical behavior associated with a given participant. In various embodiments, historical user behavior may include a browsing history for a given participant. In various embodiments, historical user behavior may include historical utilization of private state associated with a web browser by a given participant. In various embodiments, historical user behavior may include historical utilization of private state associated with a message exchange client by a given participant.

[0015] In various embodiments, determining the likelihood may also be based on historical behavior associated with the two or more participants in the ongoing message exchange topic. In various embodiments, determining the likelihood may also be based on historical behavior associated with multiple participants in multiple message exchange topics other than the ongoing message exchange topic. In various embodiments, the historical behavior associated with multiple participants in the multiple message exchange topics may include one or more associations between the content of one or more messages exchanged in the multiple message exchange topics and manual transitions of corresponding message exchange clients to a private state by one or more of the multiple participants.

[0016] In various embodiments, determining the likelihood may include applying a plurality of inputs associated with the given participant to a neural network model, wherein the neural network model is trained to provide an output including the likelihood based on the plurality of inputs. In various embodiments, the neural network model may be stored on a computing device used by the given participant to participate in the ongoing message exchange topic. In various embodiments, the neural network model may be downloaded to the computing device used by the given participant, and the neural network model may be trained using training examples obtained from a plurality of message exchange topics other than the ongoing message exchange topic.

[0017] In various embodiments, the method may further include sending a command from a first message exchange client among the two or more message exchange clients to a second message exchange client among the two or more message exchange clients to cause the second message exchange client to transition to a private state, wherein the sending is performed in response to determining that the determined likelihood satisfies one or more thresholds. Thus, the first client can control the second client to transition to a private state, thereby reducing user interaction at the second client. Furthermore, the need to determine for each client separately whether the client should transition to a private state can potentially be avoided. Instead, this determination can be performed only for the first client, with the second client also controlled based on this determination. This can reduce overall processing. In various embodiments, in the private state, one or more of the two or more message exchange clients can obfuscate at least a portion of a log of messages exchanged as part of an ongoing message exchange topic. In various embodiments, in the private state, one or more of the two or more message exchange clients can at least temporarily avoid updating the log of messages exchanged as part of the ongoing message exchange topic.

[0018] In various embodiments, the method may further include providing, by a given message exchange client of the two or more message exchange clients, responsive to determining that the likelihood satisfies the one or more thresholds, a prompt requesting permission for the given message exchange client to transition to a private state.

[0019] Furthermore, some embodiments include one or more processors of one or more computing devices, wherein the one or more processors are operable to execute instructions stored in an associated memory, and wherein the instructions are configured to cause performance of any of the foregoing methods. Some embodiments include at least one non-transitory computer-readable storage medium storing computer instructions executable by the one or more processors to perform any of the foregoing methods.

[0020] It should be understood that all combinations of the above-mentioned concepts and additional concepts described in more detail herein are considered to be part of the subject matter disclosed herein. For example, all combinations of the claimed subject matter appearing at the end of this disclosure are considered to be part of the subject matter disclosed herein. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 is a diagram of an example environment in which implementations disclosed herein may be implemented.

[0022] Figure 2 Icon used when triggering the application to switch to private state Figure 1 Examples of components of the sample environment.

[0023] Figure 3 Diagram used when training one or more machine learning models Figure 1 Examples of components of the sample environment.

[0024] Figure 4A and Figure 4B Each illustrates an example client device and one or more examples of how a private mode may be automatically triggered.

[0025] Figure 4C Illustrated is an example of a transcription of a message exchange topic that has been partially obfuscated.

[0026] Figure 5 is a flow chart illustrating an example method of automatically transitioning an application to a private state according to implementations disclosed herein.

[0027] Figure 6 An example architecture of a computing device is illustrated. DETAILED DESCRIPTION

[0028] exist Figure 1, an example environment in which the techniques disclosed herein may be implemented is illustrated. The example environment includes a communication network 101 that facilitates communication between various components in the environment. In some implementations, the communication network 101 may include the Internet, one or more intranets, and / or one or more bus subsystems. The communication network 101 may optionally utilize one or more standard communication technologies, protocols, and / or inter-process communication technologies.

[0029] The example environment also includes one or more client devices 106 1-N , electronic communication system 110, privacy state system 120, training engine 135, and training example engine 137. The example environment also includes user data 158, training examples 152, and machine learning model 156. User data 158, training examples 152, and machine learning model 156 can each be stored in one or more corresponding computer-readable media.

[0030] Client device 106 1-N Some non-limiting examples include one or more of the following: a desktop computing device, a laptop computing device, a tablet computing device, a mobile phone computing device, a vehicle computing device (e.g., an in-vehicle communication system, an in-vehicle entertainment system, an in-vehicle navigation system), a standalone interactive speaker (e.g., a so-called "smart speaker"), or a wearable device including a computing device (e.g., a watch with a computing device, glasses with a computing device, a virtual or augmented reality computing device). Additional and / or alternative client devices may be provided. For various examples herein, client device 1061 will be assumed to be the client device of a first user, client device 1062 will be assumed to be the client device of a second user, client device 1063 will be assumed to be the client device of a third user, and so on. However, it should be understood that the privacy state system 120 can interface with each of a given user's multiple client devices and / or other electronic devices that form a coordinated "ecosystem" of client devices for the given user. For example, as described herein, the user data 158 utilized by the privacy state system 120 may include sensor-based data and / or other data based on client device 1061, as well as other data based on other electronic devices of the user of client device 1061. However, for the sake of brevity, some examples described in this disclosure will focus on a single client device of a corresponding user.

[0031] Electronic communication system 110, privacy state system 120, and / or engines 135 and / or 137 can each be implemented, for example, in one or more computing devices that communicate over a network (e.g., network 101 and / or other networks). Electronic communication system 110, privacy state system 120, and engines 135 and 137 are example components through which the systems and techniques described herein are implemented and / or can interface with the systems and techniques described herein. They can each include one or more memories for storing data and software applications, one or more processors for accessing data and executing applications, and other components to facilitate communication over a network. In some embodiments, electronic communication system 110, privacy state system 120, and / or engines 135 and / or 137 can include Figure 6 The operations performed by electronic communication system 110 , privacy state system 120 , and / or engines 135 and / or 137 may be distributed across multiple computer systems, including in whole or in part on one or more client devices 106 .

[0032] In some embodiments, one or more aspects of the electronic communication system 110, the privacy state system 120, and / or one or more of the engines 135 and / or 137 may be combined in a single system and / or may be implemented on the client device 106. 1-N For example, client device 1061 may include an instance of one or more aspects of privacy state system 120 and additionally client device 106 2-N Each of the may also include an instance of one or more aspects of the privacy state system 120. As another example, the client device 106 1-N Each of these devices may each include an instance of the electronic communication system 110 (eg, the electronic communication system 110 may be an application installed and executed on each of these devices). As yet another example, one or more aspects of the electronic communication system 110 and the privacy state system 120 may be combined.

[0033] The electronic communication system 110 may include one or more remote servers and / or one or more client-side applications associated with the exchange of one or more types of electronic communications between client devices (often referred to herein as "message exchange topics"). The types of electronic communications that may be exchanged in a message exchange topic include, for example, emails, Rich Communication Services (RCS) messages, Short Message Service (SMS) messages, Multimedia Messaging Service (MMS) messages, Over-the-Top (OTT) chat messages, social network messages, audible communications (e.g., phone calls), audio-video communications, and the like. As one example, the electronic communication system 110 may include one or more remote servers that manage message exchange topics between various client devices 106, and those various client devices 106 may optionally each include a corresponding message exchange client 107. As another example, the electronic communication system 110 may be implemented solely via client-side applications operating on the corresponding client devices.

[0034] Examples of the privacy state system 120 will be described herein with respect to users of client devices 1061. When users typically operate client devices 106 (e.g., 1061, ...) to participate in a message exchange topic, those users may be referred to as message exchange topic "participants." In some embodiments, the privacy state system 120 can be implemented in whole or in part on the client device 1061. In some embodiments, one or more of the components of the privacy state system 120 can additionally or alternatively be implemented on one or more servers remote from the client device 1061. For example, one or more components can be implemented on a remote server of the electronic communication system 110.

[0035] In various implementations, the privacy state system 120 can include a data engine 122, a privacy likelihood engine 124, a privacy transition engine 126, and / or a feedback engine 132. In some implementations, aspects of the engines 122, 124, 126, and / or 132 can be omitted, combined, and / or implemented in components separate from the privacy state system 120.

[0036] The data engine 122 selects user data 158 for use in determining the likelihood that a participant in a message exchange topic considers the content of the ongoing message exchange topic to be sensitive. In some embodiments, the user data 158 includes sensor-based data generated based on output from sensors on the participant's client device 1061 and / or other electronic devices. In some embodiments, the user data 158 additionally or alternatively includes computer-based motion data generated based on participant activity via the participant's client device 1061 and / or other electronic devices. In some embodiments, the user data 158 additionally or alternatively includes historical data indicating historical behavior associated with the participant. In some embodiments, such historical behavior may include the participant's browsing history, the participant's use of private states associated with applications such as web browsers, chat history, and / or the participant's historical use of private states associated with message exchange clients 107.

[0037] In some embodiments, user data 158 may include aggregated data associated with multiple users (or message exchange topic participants). For example, in some embodiments, aggregated user data may indicate historical behavior associated with two or more participants of an ongoing message exchange topic and / or associated with multiple participants of multiple message exchange topics outside of the ongoing message exchange topic. In some embodiments, historical behavior associated with multiple participants in multiple message exchange topics may include one or more associations between the content of one or more messages exchanged in the multiple message exchange topics and manual transitions of corresponding message exchange clients to private states by one or more of the multiple participants. As described herein, a user of a client device 1061 (i.e., a participant) may be provided with an opportunity to control whether the data engine 122 and / or other components of the privacy state system 120 can access user data 158 and / or which user data 158 can be accessed.

[0038] Sensor-based data can be generated based on, for example, output from a Global Positioning System (GPS) sensor, an accelerometer, a microphone, a camera, a gyroscope, and / or other sensors. The sensor-based data can include raw sensor data (e.g., output as received from a sensor) and / or can include generalized sensor data determined based on output from one or more sensors. For example, the sensor-based data can include raw audio data from a microphone and / or can include a generalization of the raw audio data. The generalization of the raw audio data can include, for example, the average (and / or other statistical measure) decibel level over a certain time period, a classification of the raw audio data based on applying the data to a classifier (e.g., classifications such as “noisy,” “quiet,” “music,” etc.), etc. As another example, the sensor-based data can additionally or alternatively include raw GPS data and / or can include a generalization of the GPS data. The generalization of the GPS data can include, for example, a classification of a location indicated by the GPS data (e.g., restaurant, movie theater, exercise facility), a specific location indicated by the GPS data (e.g., restaurant A, movie theater A), etc. As yet another example, the sensor-based data can additionally or alternatively include raw accelerometer data and / or a generalization of such data. Generalization of the raw accelerometer data can include average (and / or other statistical measures) speed based on the data from the accelerometer, classification of activities based on applying the data to a classifier (e.g., classifications such as "run," "walk," "stop"), and the like.

[0039] Computer-based action data generated based on user activity via the user's client device 1061 and / or other electronic devices may include, for example: calendar entries and / or other electronic documents created via the device; documents interacted with (e.g., accessed) via the device; applications currently or recently utilized via the device; the status of applications currently or recently utilized via the device; the average (or other statistical measure) of processing power consumed during a recent time period; etc.

[0040] The privacy likelihood engine 124 utilizes data selected by the data engine 122 to determine the likelihood that a particular message exchange topic participant (e.g., a user of the client device 1061) will consider the content of the ongoing message exchange topic to be sensitive. The likelihood determined by the privacy likelihood engine 124 will depend on the user data 158 and the message exchange topic content. In various embodiments, the privacy likelihood engine 124 may receive "fresh" data from the data engine 122 continuously, periodically, or at other regular and / or irregular intervals to enable dynamic determination of the likelihood that a message exchange topic participant will consider the content of the ongoing message exchange topic to be sensitive. In some embodiments, the privacy likelihood engine 124 applies the data as input to one or more of the machine learning models 156, generates outputs on these machine learning models 156 based on the input, and determines the likelihood based on the generated outputs.

[0041] The privacy transition engine 126 can be configured to transition one or more applications operating on one or more client devices 106 into and / or out of a so-called "private state." As used herein, the "private state" of an application refers to an application state in which the application takes various measures to ensure that various information associated with the operation of the application is protected, obfuscated, or simply not maintained at all. For example, when a web browser is transitioned into a private state, the web browser can avoid storing a history of websites or other network resources visited or otherwise accessed by the web browser while in the private state. Additionally, the web browser can avoid storing information such as cookies, user credentials, etc. while in the private state.

[0042] In the message exchange client application 107 1-N In the context of , a private state may refer to a state in which a message exchange client 107 avoids storing, obfuscating, and / or filtering messages exchanged between one or more participants in a message exchange topic and / or between a participant in a message exchange topic and a so-called "automated assistant." An "automated assistant" may refer to a software process with which a user can interact conversationally (e.g., using typed text or spoken input (which can be converted to text). For example, a client device 106 in the form of a standalone interactive speaker may enable a user to engage in a human-to-computer conversation with an automated assistant, in which the user may ask questions (e.g., search for documents, find information, ask for the weather / score, etc.) and / or issue commands (e.g., play a specific song, turn on lights, set a timer, save a reminder, etc.). Other client devices 106, such as smartphones, tablet computers, smartwatches, etc., may include automated assistants that facilitate similar interactive conversations with users.

[0043] The privacy transition engine 126 can determine that the likelihood determined by the privacy likelihood engine 124 meets one or more thresholds. Based on such a determination, the privacy transition engine 126 can transition to a private state, or can trigger a transition of one or more message exchange clients 107 (or more generally, client devices 106) to a private state. Various types of thresholds can be compared to the likelihood that the content of a message exchange topic will be considered sensitive to at least one participant. In some embodiments, where the likelihood calculated by the privacy likelihood engine 124 is calculated as a number or measure (e.g., in a range of 0.0 to 1.0, 0 to 100, etc.), a numerical threshold can be used. In some embodiments, multiple thresholds can be employed. For example, if the likelihood determined by the privacy likelihood engine 124 meets a first threshold but does not meet a second, higher threshold, one or more message exchange clients 107 can provide an audible or visual output in the form of a prompt requesting permission for the message exchange client 107 to transition to a private state. However, if both the first and second thresholds are met, one or more message exchange clients 107 operated by participants in the ongoing message exchange topic may automatically transition to a private state, eg, with or without notifying the respective participants operating the message exchange clients 107 .

[0044] In various embodiments where an ongoing message exchange topic involves multiple participants operating multiple message exchange clients 107, transitioning to a private state by one message exchange client 107 may or may not result in transitioning to a private state by one or more of the other message exchange clients 107. For example, in some embodiments, a first message exchange client 107 transitioning to a private state may send a command to a second message exchange client causing the second message exchange client to transition to a private state. In some embodiments, this transmission may occur in response to a determination, such as by the privacy transition engine 126, that the likelihood determined by the privacy likelihood engine 124 satisfies one or more thresholds.

[0045] Assume that, by an instance of the privacy state system 120 operating on a given client device 106 (including corresponding instances of the data engine 122, the privacy likelihood engine 124, and / or the privacy transition engine 126), it is determined that there is a certain likelihood that a participant operating a corresponding message exchange client 107 on a given client device 106 will consider the content of an ongoing message exchange topic to be sensitive. Assume further that the likelihood satisfies a first threshold value, but not a second, higher threshold value. In some embodiments, such a scenario causes the privacy transition engine 126 to transition only the local message exchange client 107 to a private state. In other embodiments, such a scenario causes the local message exchange client 107 to transition to a private state and request that other message exchange clients 107 currently participating in the message exchange topic transition to a private state (in which case they may, for example, prompt the corresponding message exchange topic participants for permission).

[0046] The feedback engine 132 can use the requested and / or unsolicited feedback from the user / participant of the client device 106 to provide to the training example engine 137. The training example engine 137 can utilize the feedback when generating additional training examples in order to refine one or more of the machine learning models 156. As an example, assume that a participant in a message exchange topic manually transitions her corresponding message exchange client 107 to a private state. The feedback engine 132 can provide the training example engine 137 with an indication of the manual transition, as well as the various inputs currently applied to the manually transitioned participant (e.g., user data 158, content of the message exchange topic). The training example engine 137 can then utilize this data to generate training example inputs for training examples, and can generate training example outputs for training examples based on the manual transition of the message exchange client 107 to the private state.

[0047] Figure 2 The diagram is used when determining the likelihood that participants in a message exchange thread will consider the content of an ongoing message exchange thread to be sensitive. Figure 1 An example of the components of the sample environment. Figure 2In the example embodiment, user data 158 is generated based on output from sensors 204 of client device 1061, state and / or other data from applications 206 of client device 1061, documents 208 created and / or accessed via client device 1061, and historical data 210 indicating historical behavior associated with participants in a message exchange thread operating client device 1061. Output from sensors 204 is used to generate sensor-based data for user data 158. Output from applications 206 and documents 208 is used to generate computer-based action data for user data 158. Historical data 210 is used to create / identify historical behavior for user data 158. In some embodiments, user data 158 can be generated based on output generated by a user's sensors and / or user actions performed via an additional or alternative electronic device of the user (e.g., sensors of a user's watch in electronic communication with client device 1061).

[0048] The data engine 122 selects a subset of the data 201A from the user data 158 for provision to the privacy likelihood engine 124. Figure 2 In the example, the privacy likelihood engine 124 may apply data 201A along with message exchange topic content 212 as input to one of the machine learning models 156 and generate an output based on the applied input. The generated output may directly indicate the likelihood that a participant in the message exchange topic would consider the content of the message exchange topic sensitive and may be provided to the privacy transformation engine 126. As an example, the input applied to the machine learning model may be a vector of values ​​based on data 201A and including sensor-based data, computer-based motion data, and historical behavioral data, as well as the content 212 of the ongoing message exchange topic. The content 212 of the ongoing message exchange topic may include text and / or other content (e.g., images, sounds, etc.) that has been inserted into the ongoing message exchange topic (e.g., by a participant operating a message exchange client 107). The output 203A may indicate, for example, the likelihood that a participant in the message exchange topic would consider the content of the message exchange topic (whether already inserted into the topic or upcoming) to be sensitive.

[0049] Based on the output 203A, the privacy transition engine 126 determines whether to transition the local message exchange client 107 operating on the client device 1061 to a private state. In some embodiments, the privacy transition engine 126 also transitions the local message exchange client 107 operating on the client device 1061 to a private state, for example, to the operating message exchange topic 107 being used by the participants to participate in the ongoing message exchange topic. 1-N One or more other client devices 106 2-N Send Privacy Command 205 1-NAs noted above, in various embodiments, the other client devices 106 2-N The transition to the private state may be automatic, their respective participants may be prompted for permission to transition to the private state, and the like.

[0050] In some embodiments, the privacy transformation engine 126 directly converts the privacy command 205 1-N In some other embodiments, the privacy transformation engine 126 sends the privacy command 205 to the corresponding additional client device 106. 1-N The privacy command 205 is sent to one or more intermediate components (e.g., the electronic communication system 110), which then sends the status notification to the corresponding additional client devices. In some embodiments, the privacy transformation engine 126 automatically sends the privacy command 205 1-N In some other embodiments, the privacy transformation engine 126 sends the privacy command 205 only in response to an affirmative user interface input from a user provided via the client device 1061. 1-N .although Figure 2 Three separate privacy commands are illustrated as being provided to different client devices, however in some embodiments more or fewer privacy commands may be sent and / or may be sent for presentation to more or fewer additional message exchange topic participants.

[0051] Figure 3 The picture is in the Figure 2 Used in training one or more machine learning models 156 used in determining the likelihood that a message exchange participant would consider the content of an ongoing message exchange topic to be sensitive Figure 1 Examples of components of the sample environment.

[0052] exist Figure 3 , training data instance 136 1-NReceived by training example engine 137. Each training data instance includes the content of a message exchange topic and other input (e.g., sensor-based data, computation-based action data, historical data) that can be applied to a particular message exchange topic participant, for example, when a message exchange client 107 operated by the participant is transitioned (automatically or manually) into or out of a private state. For example, training data instance 1361 may include the content of the message exchange topic, a data value, and a first vector indicating whether the transition to the private state was automatic or manual. Additionally, for example, training data instance 1362 may include the content of the message exchange topic, a data value, and a second vector indicating whether the transition to the private state was automatic or manual. In some embodiments, at least some of the training data instances may be generated based on the corresponding message exchange topic participant manually transitioning a message exchange client 107 into (or out of) a private state. Additionally or alternatively, in some embodiments, at least some of the training data instances may be generated based on the corresponding message exchange client 107 being automatically transitioned into (or out of) a private state. Additional or alternative techniques for generating training data instances may be utilized.

[0053] The training example engine 137 uses the training examples to generate training examples 154 1-N . Training examples 154 1-N Each of includes a training example input based on data of the corresponding training data instance, and a training example output indicating whether a transition, for example, into (or out of) a private state is desired or undesirable (which can be determined, for example, from the feedback engine 132).

[0054] Generated training examples 154 1-N The training examples 152 are stored as training examples utilized by the training engine 135 to train at least one of the machine learning models 156. In some implementations, the training engine 135 trains the machine learning model based on the training examples 152 based on application of training example inputs to the training examples and backpropagation based on training example outputs of the training examples.

[0055] In some embodiments, the same trained machine learning model 156 can be used for client device 1061 and for other client devices of other users. In some embodiments, the trained machine learning model 156 used for client device 1061 can optionally be further trained based on user data 158 of a message exchange topic participant operating client device 1061 and / or based on feedback from the participant provided by feedback engine 132. Further training of the machine learning model 156 based on user data 158 and / or based on feedback from the message exchange topic participant can enable the machine learning model to be further customized for the message exchange topic participant operating a particular client device 106. As an example, past data from user data 158 can directly indicate a participant's transition to / from private status and associated data, and can be utilized by training example engine 137 to generate one or more additional training examples for use by training engine 135.

[0056] Now go to the figure reference Figures 4A to 4C , provides additional description of various components and techniques described herein. Figure 4A and Figure 4B Graphic Figure 1 Example client device 1061 and message exchange client ( Figure 4A and Figure 4B One or more examples of how a message exchange topic (not depicted in FIG) may be transitioned to a private state in response to a determination that there is a sufficient probability that at least one participant in an ongoing message exchange topic would consider content of the message exchange topic sensitive. Figure 4A and Figure 4B The client device 1061 includes a display screen 140. The display screen 140 also includes system interface elements 481, 482, 483, which can be interacted with by a user to cause the client device 1061 to perform one or more actions.

[0057] exist Figure 4A , the first message exchange topic participant ( Figure 4A, has provided a first message of “I want to tell you something…” to the ongoing message exchange topic. Another participant, Sally, replies “What is it?” The first participant then says “Can you keep this between us?” In various embodiments, such statements may be considered “privacy trigger phrases” that, when detected, cause the message exchange client 107 (operated by the first participant) to Figure 4A 480). As noted above, privacy trigger phrases may include other similar phrases such as "off the record," "let's keep this between us," "can you promise not to tell anyone?", and the like. In some such embodiments, one or more messages immediately following (or, in some cases, preceding) such a privacy trigger phrase may not be retained, e.g., until the first participant manually takes the message exchange client out of private mode or until it is detected that the topic of discussion has changed to a less sensitive subject. Thus, for example, Sally's "OK" reply and the message content subsequently provided by the first participant (i.e., the content enclosed by box 480) may not be retained in the transcription or log of the ongoing message exchange thread. Additionally or alternatively, in some embodiments, messages exchanged immediately following the transition may be obfuscated (e.g., replaced with meaningless text or symbols, or redacted) before being stored in the transcription or log.

[0058] The privacy trigger phrases may be manually configured or learned over time. For example, the privacy trigger phrase may simply be a topic content 212 (see FIGURE 212 ) that is applied by a machine learning model (along with one or more other inputs) to determine the likelihood that a participant in a message exchange topic will consider the message exchange topic sensitive. Figure 2) is a component of the machine learning model. In some embodiments, privacy trigger phrases can be learned when message exchange topic participants provide certain phrases immediately before or after manually transitioning a message exchange client 107 to a private state. Thus, for example, as more message exchange topic participants transition their message exchange clients 107 to a private state before or after stating something like "Can we keep this on the downlow?", such phrases can be used as part of a growing number of training examples for training the machine learning model. Of course, a message exchange topic can be taken out of private in response to other so-called "non-privacy trigger phrases." For example, phrases such as "on alighter note..." or "let's go back on the record" can trigger one or more message exchange clients 107 to transition from a private state to a non-private state.

[0059] In addition to or in lieu of a privacy trigger phrase, in some embodiments, one or more n-grams that, alone or in combination, form part of the content of the message exchange topic may be used as a signal. Figure 4B In the example, a first message exchange topic participant operating client device 1061 has provided a first message of "Guess what?" to the ongoing message exchange topic. Another participant, Sally, replies "What?" The first participant then declares "Bob got fired for stealing $!" In various embodiments, various n-grams of such statements (such as the name of a particular known entity ("Bob") or other n-grams (e.g., "fired," "steal")) can, alone or in combination, trigger a message exchange client 107 (operated by the first participant) to be fired. Figure 4B (not depicted in FIG) to transition to a private state (or at least to prompt the first participant as to whether they wish to transition to a private state). Additionally, although Figure 4B All trigger n-grams in are contained in a single statement made by the first participant, but this is not intended to be limiting. In various embodiments, n-grams from different messages provided by different participants can also be used in combination to trigger the message exchange client to transition to a private state.

[0060] Figure 4C depiction Figure 4B. In this example, the message from the first participant stating "Bot got fired for stealing$" has been at least partially obfuscated, such that the name "Bob" and the n-gram "stealing" have been scrambled. In various embodiments, this content can be preserved rather than the uncensored content to prevent others from viewing potentially sensitive statements.

[0061] In addition to or in lieu of the signals identified above that can trigger a message exchange client to transition to a private state, in some embodiments, the general topic of discussion (alone or in combination with aspects of historical user behavior) can trigger a transition to a private state. For example, in some embodiments, discussion of potentially sensitive topics such as health issues, vulgar language, politics, personal information, financial information, etc. can cause a message exchange client (or all message exchange clients participating in a message exchange topic) to transition to a private state. Of course, which topics trigger a transition to a private state can change and / or evolve over time. For example, and as described above, various machine learning models can be continuously trained over time to identify when potentially sensitive topics are being discussed. For example, one or more machine learning models can be trained with training examples representing instances in which a particular topic was discussed in a message exchange topic and one or more message exchange topic participants manually caused their respective message exchange clients to transition to a private state.

[0062] Additionally or alternatively, one or more machine learning models may be trained with training examples representing instances in which a particular topic is discussed in a message exchange topic and one or more message exchange clients are automatically transitioned to a private state (and the corresponding participants do not provide negative feedback or provide positive feedback). Similar techniques may be used to automatically cause message exchange clients to be taken out of a private state. For example, assume that one or more participants in a message exchange topic are discussing a sensitive topic, which causes one or more of their corresponding message exchange clients 107 to transition to a private state. Also assume that the participants change the topic of discussion to a less sensitive topic. In various embodiments, the change of topic may trigger one or more message exchange clients 107 to transition from a private state back to a non-private state (wherein the message exchange topic content is not obfuscated and retained in native form).

[0063] Various techniques can be used to determine the discussion topics in a message exchange topic. In some embodiments, one or more topic classifiers can be used to identify one or more current topics of discussion, for example, based on the progress of a sliding window of the message exchange topic content. The topic classifier can take the form of a machine learning model or a rule-based model. Using a machine learning-based topic classifier, in some embodiments, the topic classifier can be trained to provide an output (e.g., a binary output or probability) indicating whether a particular topic is being discussed. In other embodiments, the topic classifier can be trained to provide an output indicating whether a plurality of different topics are being discussed. For example, a topic classifier can be configured to provide an output indicating the likelihood or confidence of a plurality of different topics being discussed. In some embodiments, only those topics with the likelihood / confidence that meet one or more thresholds can be identified as discussion topics. In other embodiments, only the n highest likelihood / confidence topics can be identified as discussion topics.

[0064] As described above, in addition to the content of the message exchange topic, other signals may be considered in determining the likelihood that the content of an ongoing message exchange topic is likely to be considered sensitive by at least one message exchange topic participant. In some implementations, contextual signals or cues (e.g., Figure 2 Assume that a particular message exchange topic participant prefers to manually transition the message exchange client to a private state during particular moments and / or while the participant is in a particular location. In various embodiments, the participant's message exchange client can be automatically transitioned to a private state during those same moments and / or while the participant is in the same particular location.

[0065] In some embodiments, the state of one or more applications operating on client device 106 can also be used to determine the likelihood that the content of the ongoing message exchange topic is likely to be considered sensitive by at least one of the message exchange topic participants. Assume that a particular message exchange topic participant operating a message exchange client 107 on client device 106 also has a web browser open on client device 106, and that the web browser is manually transitioned to a private state. In some embodiments, particularly if the participant (or participants generally) tends to transition message exchange client 107 to a private state while browsing in a private state, the fact that the web browser is currently in a private state can (alone or in combination with other signals described herein) trigger the message exchange client to also transition to a private state. More generally, in some embodiments, when a message exchange client 107 is transitioned to a private state (either manually by a message exchange participant or automatically without negative feedback), one or more states of one or more other applications operating on the participant's client device 106 can be used as features of a vector, which is used as a training example to (further) train a machine learning model.

[0066] Documents (e.g., Figure 2 208). Assume that a user has a document stored on his client device 106 (and / or in a cloud storage unit), and that the document is configured with strict security protection (e.g., password protected, a limited number of users who can access it, encrypted, etc.). In some embodiments, topics associated with the document and / or its metadata can be marked as sensitive based on the strict security protection. In some embodiments, discussion of such topics by the owner of the document in a message exchange topic can trigger a message exchange client 107 operated by the owner to transition to a private state. Additionally or alternatively, if the document owner or another message exchange topic specifically references the document in the message exchange topic (e.g., provides a link to the document, permission to access the document, etc.), one or more message exchange clients 107 operated by participants of the message exchange topic can be caused to transition to a private state.

[0067] While the examples described herein generally include multiple human message exchange topic participants, this is not intended to be limiting. As noted above, in some embodiments, a message exchange topic may exist between a single human participant and a non-human participant (such as an automated assistant). In some such embodiments, the techniques described herein may be employed to automatically transition a message exchange client used by a human participant to a private state, for example, to avoid persisting or obscuring messages exchanged with an automated assistant.

[0068] In some embodiments, it is possible that the techniques described herein can be used to obfuscate or otherwise avoid persisting messages exchanged between purely non-human participants. For example, messages exchanged between multiple automated assistants associated with different applications, domains (e.g., a personal automated assistant exchanging messages with a food delivery automated assistant), etc., can be obfuscated and / or not stored based on the messages containing content that is likely to be considered sensitive to one or more humans (e.g., a user on whose behalf one or more of the automated assistants are acting and / or a user served by one or more of the automated assistants).

[0069] Assume that a first person is shopping for a birthday present for a second person. Also assume that both people tend to interact with the same automated assistant, operated, for example, by a standalone interactive speaker in their residence. If the first person engages in a human-to-computer conversation utilizing the automated assistant to search for a suitable birthday present, the first person is likely to consider any messages exchanged with the automated assistant to be sensitive, as the first person would not want the second person to consume the content. Thus, the automated assistant can, for example, respond to a spoken n-gram such as "birthday present" and the identity of the second person, or to an utterance such as "What should I get Alice for her birthday?" to transition to a private state in which the automated assistant ceases to retain the content of the human-to-computer conversation between the first person and the automated assistant. Additionally or alternatively, if the first person uses a graphical user interface, such as message exchange client 107, to converse with the automated assistant, message exchange client 107 can transition to a private state. A similar transition to a private state can occur during a human-to-computer conversation when, for example, humans discuss potentially sensitive topics, such as finances, health, or other topics known or learned to be sensitive.

[0070] Figure 51 is a flow chart illustrating an example method 500 for determining the likelihood that the content of a message exchange topic may be considered sensitive by one or more participants and causing one or more message exchange clients or other components to transition to a private state, according to embodiments disclosed herein. For convenience, the operations of the flow chart are described with reference to a system performing the operations. This system may include various components of various computer systems, such as one or more components of the privacy state system 120. Furthermore, while the operations of method 500 are shown in a particular order, this is not intended to be limiting. One or more operations may be reordered, omitted, or added.

[0071] At block 502, the system checks the content of the ongoing message exchange topic. As noted above, in some embodiments, the system can use a sliding window to check the specific portion of the ongoing message exchange topic. In various embodiments, the size of the sliding window can be determined in time and / or in space. For example, the sliding window of the checked content can only include content from the last x minutes, last y messages, etc. (wherein x and y are non-zero integers). In other embodiments, each message or even each part of each message incorporated into the message exchange topic can be checked. In various embodiments, the message exchange participant can have the option of disabling this inspection (which will prevent the remaining operations of method 500 from being executed).

[0072] At block 504, the system may determine, based at least in part on the inspection of block 502, the likelihood that the content of the message exchange topic will be considered sensitive by one or more message exchange topic participants. In some embodiments, this likelihood may be determined based solely on the content of the message exchange topic (e.g., privacy trigger phrases, various combinations of n-grams, sensitive discussion topics, etc.). In other embodiments, this likelihood may be additionally determined based on other signals, such as sensor data from one or more client devices operated by message exchange topic participants, documents stored or otherwise controlled by one or more message exchange participants, historical behavior of one or more message exchange topic participants (e.g., under what circumstances a participant manually triggers a transition to a private state or does not object to an automatic transition to a private state), etc. As noted above, in some embodiments, various inputs may be taken from the message exchange topic content and / or from these other signals and applied as input to a machine learning model. The machine learning model may be trained to provide an output indicating the likelihood.

[0073] At block 506, the system can determine whether the likelihood determined at block 504 meets a first threshold. If the answer is no (e.g., the likelihood that any participant would consider the message exchange topic content to be sensitive is relatively low), method 500 can continue back to block 502, and the examination of the message exchange topic content can be restarted. However, if the answer at block 506 is yes, method 500 can proceed to block 508. At block 508, the system can determine whether the likelihood determined at block 504 meets a second threshold, which in many cases can be higher than the first threshold associated with block 506. If the answer at block 508 is yes (e.g., the message exchange content is very likely to be considered sensitive to one or more message exchange topic participants), method 500 can proceed to block 510. At block 510, one or more message exchange clients operated by one or more message exchange topic participants can be automatically transitioned to a private state in which the content of the message exchange topic is obscured or not retained.

[0074] On the other hand, if the answer at block 508 is no (e.g., there is a possibility that the message exchange topic participants will consider the message exchange topic content to be sensitive but the possibility is not certain to be so high), method 500 can proceed to block 512. At block 512, a prompt requesting permission from one or more message exchange topic participants to transition the message exchange client to a private state can be provided, for example, by a message exchange client as an audible output or a visual output. At block 514, if the participants grant the requested permission, method 500 can proceed to block 510 described previously. If the answer at block 514 is no, method 500 can continue back to block 502 and the transition to a private state can not be triggered.

[0075] Returning to block 510, in some embodiments, the system may send, or cause one or more message exchange clients to send, one or more privacy commands to other message exchange clients (or more generally, client devices) being used to participate in a message exchange topic. These privacy commands may cause the recipient message exchange client (or more generally, the recipient client device) to transition (e.g., automatically or in response to a user providing permission when prompted) to a private state. Although Figure 5 Not depicted, but in some embodiments, transmission of the privacy command to the various message exchange clients can be conditional on the likelihood determined at block 504. If the likelihood meets a particular threshold (e.g., a second threshold associated with block 508), the privacy command can be automatically sent. However, if the likelihood fails to meet such a threshold, the privacy command can be sent only in response to the participant granting such permission (e.g., in response to a prompt requesting such permission).

[0076] In addition to or in lieu of prompting a message exchange topic participant for permission to transition a message exchange client to a private state, in some embodiments, the message exchange client can be automatically transitioned, and the participant can then have an opportunity to provide feedback about the automatic transition. For example, a user can be notified, for example, via an audible output or a visual output, that their client device and / or message exchange client has transitioned to a private state. The participant can then provide feedback, such as manually transitioning back to a non-private state or providing other input indicating disapproval of the transition. Based on this feedback, the system can "learn" (e.g., by using this instance as the basis for a machine learning model training example) that in the current situation, the participant does not wish to transition to a private state. Of course, unlike Figure 5 Techniques similar to those depicted in can be used to bring a message exchange client (or more generally, a client device) out of a private state and into a non-private (or less private) state.

[0077] In various embodiments, the message exchange client may operate on a client device along with any number of other applications. In some embodiments, one or more of these other (e.g., third-party) applications may be able to "listen" to a message exchange topic participated in by the message exchange client. For example, a takeout ordering application may listen to a message exchange topic between users to determine, for example, whether the users are discussing dinner (in which case the takeout ordering application may join the message exchange topic and offer to place a takeout order). As another example, in some embodiments, one or more search applications may be listening to a message exchange topic to determine whether to use the exchange content to prepare and submit a search query. In any case, in some embodiments, if the participants in the message exchange are determined to be discussing potentially sensitive information, thereby causing one or more message exchange clients to transition to a private state, the content of the message exchange topic may be obscured or otherwise not provided to such third-party applications.

[0078] Figure 6 is a block diagram of an example computing device 610 that may optionally be utilized to perform one or more aspects of the techniques described herein. 1-N , privacy state system 120 , and / or one or more of the other components may include one or more components of the example computing device 610 .

[0079] The computing device 610 typically includes at least one processor 614 that communicates with a number of peripheral devices via a bus subsystem 612. These peripheral devices may include a storage subsystem 624 (including, for example, a memory subsystem 625 and a file storage subsystem 626), a user interface output device 620, a user interface input device 622, and a network interface subsystem 616. The input and output devices allow a user to interact with the computing device 610. The network interface subsystem 616 provides an interface to an external network and couples to corresponding interface devices in other computing devices.

[0080] The user interface input devices 622 may include a keyboard, a pointing device (such as a mouse, trackball, touchpad, or graphic tablet), a scanner, a touch screen incorporated into a display, a voice input device (such as a voice recognition system, an audio input device such as a microphone, and / or other types of input devices. In general, the use of the term "input device" is intended to include all possible types of devices and methods for inputting information into the computing device 610 or onto a communication network.

[0081] The user interface output device 620 may include a display subsystem, a printer, a fax machine, or a non-visual display (such as an audio output device). The display subsystem may include a cathode ray tube (CRT), a flat panel device (such as a liquid crystal display (LCD)), a projection device, or some other mechanism for creating a visible image. The display subsystem may also provide a non-visual display, such as via an audio output device. In general, the use of the term "output device" is intended to include all possible types of devices and methods for outputting information from the computing device 610 to a user or to another machine or computing device.

[0082] The storage subsystem 624 stores programming and data structures that provide the functionality of some or all of the modules described herein. For example, the storage subsystem 624 may include a Figure 5 The logic of selected aspects of method 500.

[0083] These software modules are typically executed by the processor 614 alone or in combination with other processors. The memory subsystem 625 used in the storage subsystem 624 may include a number of memories, including a main random access memory (RAM) 630 for storing instructions and data during program execution and a read-only memory (ROM) 632 for storing fixed instructions. The file storage subsystem 626 may provide persistent storage for program and data files and may include a hard drive, a floppy disk drive and associated removable media, a CD-ROM drive, an optical drive, or a removable media cartridge. Modules implementing the functionality of a particular embodiment may be stored by the file storage subsystem 626 in the storage subsystem 624 or in other machines accessible by the processor 614.

[0084] The bus subsystem 612 provides a mechanism for the various components and subsystems of the computing device 610 to communicate with each other as intended. Although the bus subsystem 612 is shown schematically as a single bus, alternative implementations of the bus subsystem may use multiple busses.

[0085] The computing device 610 may be of varying types, including a workstation, server, computing cluster, blade server, server farm, or any other data processing system or computing device. Due to the ever-changing nature of computers and networks, Figure 6 The description of the computing device 610 depicted in FIG is intended only as a specific example for purposes of illustrating some embodiments. Many other configurations of the computing device 610 may have Figure 6 The computing device may have more or fewer components than those depicted.

[0086] In situations where the systems described herein collect or otherwise monitor personal information about a user or can utilize personal and / or monitored information (e.g., messages exchanged in a message exchange thread), the user can be provided with an opportunity to control whether a program or feature collects user information (e.g., information about the user's social network, social actions or activities, occupation, preferences, or current geographic location) or to control whether and / or how content that may be more relevant to the user is received from a content server. In addition, certain data can be processed in one or more ways before it is stored or used so that personally identifiable information is removed. For example, the user's identity can be processed so that personally identifiable information cannot be determined for the user, or the user's geographic location can be generalized (such as to a city, zip code, or state level) if geographic location information is obtained so that the user's specific geographic location cannot be determined. Thus, the user can control how information is collected and / or used about the user. For example, in some embodiments, a participant in a message exchange thread operating a message exchange client configured with selected aspects of the present disclosure can choose not to monitor message exchange thread content, for example, so that a participant who wishes to transition the message exchange client to or from a private state can do so manually.

[0087] Although several embodiments have been described and illustrated herein, various other means and / or structures for performing the functions and / or obtaining the results and / or one or more advantages described herein may be utilized, and each of such variations and / or modifications is considered to be within the scope of the embodiments described herein. More generally, all parameters, dimensions, materials, and configurations described herein are intended to be exemplary, and the actual parameters, dimensions, materials, and / or configurations will depend on the specific application or applications to which the teachings are applied. Those skilled in the art will recognize or be able to ascertain many equivalents to the specific embodiments described herein using no more than routine experimentation. Therefore, it should be understood that the above embodiments are presented by way of example only and that within the scope of the appended claims and their equivalents, embodiments may be practiced in other ways than those specifically described and claimed. Embodiments of the present disclosure are directed to each individual feature, system, article, material, kit, and / or method described herein. In addition, any combination of two or more such features, systems, articles, materials, kits, and / or methods is included within the scope of the present disclosure insofar as such features, systems, articles, materials, kits, and / or methods do not conflict with each other.

Claims

1. A method for automatically transitioning an application, implemented using one or more processors, comprising: determining that a first application executed by one or more of the processors has transitioned to a private state for the first application; as well as in response to determining that the first application has transitioned to a private state for the first application, automatically transitioning a second application executed by one or more of the processors to a private state for the second application, wherein the second application is distinct from the first application and comprises a message exchange client operable to incorporate a message into a message exchange topic; wherein the message exchange client stores one or more messages incorporated into the message exchange topic in a transcription of messages presented by the message exchange client prior to the automatic transition; and wherein the message exchange client refrains from storing one or more messages incorporated into the message exchange topic in the message transcription after the automatic transition.

2. The method according to claim 1, wherein In the private state of the first application, the first application avoids storing information about its operations in logs.

3. The method according to claim 2, wherein: The first application includes a web browser.

4. The method according to claim 3, wherein: The log includes browsing history.

5. The method according to claim 1, wherein The message exchange client is a first message exchange client, and the message exchange topic involves a plurality of participants operating a plurality of message exchange clients.

6. The method according to claim 5, further comprising sending a command to a second message exchange client among the plurality of message exchange clients, causing the second message exchange client to transition to the private state, wherein: The sending is performed in response to the automatic transition.

7. The method according to claim 1, wherein The message exchange topics include Simple Messaging Service ("SMS") or Multimedia Messaging Service ("MMS") exchanges.

8. The method according to claim 1, wherein The message exchange topic includes a human-to-computer conversation with an automated assistant.

9. The method according to claim 1, wherein The automatic transition is also based on historical behavior associated with at least one participant of the message exchange topic.

10. A method for automatically transitioning an application, implemented using one or more processors, comprising: examining an ongoing message exchange topic involving at least one human participant, a first automated assistant, and a second automated assistant; determining, based at least in part on the examining, a likelihood that one or more messages incorporated into the message exchange topic by the at least one human participant or the first automated assistant will be considered private by at least one participant; determining that the determined likelihood satisfies one or more thresholds; as well as In response to determining that the determined likelihood satisfies one or more thresholds, refraining from storing in a message log the one or more messages exchanged between the first automated assistant and the second automated assistant, wherein the likelihood is determined based on detecting one or more n-grams classified as sensitive in the ongoing message exchange topic, and wherein the one or more n-grams are classified as sensitive based on historical behavior associated with a plurality of participants in a plurality of message exchange topics other than the ongoing message exchange topic.

11. The method according to claim 10, wherein: The likelihood is also determined based on historical behavior associated with the at least one participant.

12. The method according to claim 10, wherein: The likelihood is further determined based on detecting one or more topics or metadata associated with a document controlled by the at least one participant in the ongoing message exchange topic.

13. The method according to claim 10, wherein: The one or more n-grams are classified as sensitive based on historical behavior associated with the at least one participant.

14. The method according to claim 10, wherein: The one or more n-grams are classified as sensitive based on browsing history associated with a plurality of users.

15. A system comprising one or more processors and a memory operatively coupled to the one or more processors, wherein: The memory stores instructions that, in response to execution by one or more processors, cause the one or more processors to perform any one of the methods according to claims 1-14.

16. At least one non-transitory computer-readable medium comprising instructions that, in response to being executed by one or more processors, cause the one or more processors to perform any one of the methods of claims 1-14.

Citation Information

Patent Citations

  • System and method for in-private browsing

    US20120240237A1

  • System and Method for Conducting Private Messaging

    US20150288633A1